s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-53b1fda699801c9de8888444132062ebeea7698b6e9b4c670dbbf5591a08962d high

📛 Threat Title

Mirai: axis.sh4

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 148200 bytes. Tags: Gafgyt, Mirai. Reporter: BlinkzSec. First seen: 2026-05-14 19:23:10.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 53b1fda699801c9de8888444132062ebeea7698b6e9b4c670dbbf5591a08962d 1 feed

IOC database

Type
hash_sha256
Value
53b1fda699801c9de8888444132062ebeea7698b6e9b4c670dbbf5591a08962d
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 5389de0f6753e453763878ab4f7632f8c9b7a3f6 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/5389de0f6753e453763878ab4f7632f8c9b7a3f6
1 feed

IOC database

Type
hash_sha1
Value
5389de0f6753e453763878ab4f7632f8c9b7a3f6
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/5389de0f6753e453763878ab4f7632f8c9b7a3f6

hash_md5 bb5fc1b365f1ef1829a0f302e9485041 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/bb5fc1b365f1ef1829a0f302e9485041
1 feed

IOC database

Type
hash_md5
Value
bb5fc1b365f1ef1829a0f302e9485041
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/bb5fc1b365f1ef1829a0f302e9485041

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 148200 bytes. Tags: Gafgyt, Mirai. Reporter: BlinkzSec. First seen: 2026-05-14 19:23:10.

Remediations (10)

  • web:academic.oup.com

    The ISP has been mitigating IoT infections of the Mirai family based on the abuse data it receives. We briefly discuss Mirai and then describe the notification mechanisms of the ISP, as well as the remediation steps that the users are asked to perform. Mirai malware.

  • web:dailysecurityreview.com

    The Mirai botnet, a notorious piece of malware, launched devastating DDoS attacks in 2016. This blog post delves into its origins, spread, impact, and the ongoing threat it represents, providing crucial information on mitigating Mirai botnet risks.

  • web:echoxec.com

    Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...

  • web:ieeexplore.ieee.org

    Mirai virus is known since 2016 and now has become a critical source of insecurity for the internet of things. This botnet takes over the devices infected by it to orchestrate massive Distributed Denial of Service attacks. This essay will describe the construction of Mirai , how it works, and how it has grown with time, with special attention to how it acquires its botnet using default login ...

  • web:link.springer.com

    This chapter discussed most of the related work of Mirai malware along with the existing mitigation strategy with the issues. The next chapter discusses the proposed methodology for mitigating the Mirai at the network level.

  • web:rruzi.github.io

    In terms of the communication mechanism, Mirai .CatDDoS basically follows the original design of Mirai , except that the fixed 4-byte \x00\x00\x00\x01 when Mirai goes online is modified to a fixed 8-byte: \x31\x73\x13\x93\x04\x83\x32\x04 In terms of the ATTACK_VECTOR, Mirai .CatDDoS implements a richer variety of DDoS attack types than Mirai .

  • web:westoahu.hawaii.edu

    A botnet called Mirai infected hundreds of thousands of Internet of Things (IoT) devices, amassing a wide network of compromised devices. Mitigations against the Mirai botnet involve taking proactive security measures, properly hardening systems, and updating to the latest software to reduce the risk of compromise.

  • web:www.akamai.com

    Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .

  • web:www.joesandbox.com

    Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file Yara detected Mirai mirai .sh4.elf started Sample deletes itself

  • web:www.quorumcyber.com

    Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.